Search CVE reports
11 – 16 of 16 results
CVE-2016-10130
Medium priorityThe http_connect function in transports/http.c in libgit2 before 0.24.6 and 0.25.x before 0.25.1 might allow man-in-the-middle attackers to spoof servers by leveraging clobbering of the error variable.
1 affected packages
libgit2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgit2 | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2016-10129
Medium priorityThe Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via an empty packet line.
1 affected packages
libgit2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgit2 | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2016-10128
Medium priorityBuffer overflow in the git_pkt_parse_line function in transports/smart_pkt.c in the Git Smart Protocol support in libgit2 before 0.24.6 and 0.25.x before 0.25.1 allows remote attackers to have unspecified impact via a crafted...
1 affected packages
libgit2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgit2 | Not affected | Not affected | Not affected | Not affected | Vulnerable |
CVE-2016-8569
Low prioritySome fixes available 2 of 5
The git_oid_nfmt function in commit.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a cat-file command with a crafted object file.
1 affected packages
libgit2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgit2 | — | Not affected | Not affected | Not affected | Fixed |
CVE-2016-8568
Medium prioritySome fixes available 2 of 5
The git_commit_message function in oid.c in libgit2 before 0.24.3 allows remote attackers to cause a denial of service (out-of-bounds read) via a cat-file command with a crafted object file.
1 affected packages
libgit2
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
libgit2 | — | Not affected | Not affected | Not affected | Fixed |
CVE-2014-9390
Medium prioritySome fixes available 26 of 41
Git before 1.8.5.6, 1.9.x before 1.9.5, 2.0.x before 2.0.5, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 on Windows and OS X; Mercurial before 3.2.3 on Windows and OS X; Apple Xcode before 6.2 beta 3; mine all versions before...
5 affected packages
git, git-core, jgit, libgit2, mercurial
Package | 24.04 LTS | 22.04 LTS | 20.04 LTS | 18.04 LTS | 16.04 LTS |
---|---|---|---|---|---|
git | Fixed | Fixed | Fixed | Fixed | Fixed |
git-core | Not in release | Not in release | Not in release | Not in release | Not in release |
jgit | Not affected | Not affected | Not affected | Not affected | Not affected |
libgit2 | Not affected | Not affected | Not affected | Not affected | Not affected |
mercurial | Not affected | Not affected | Not affected | Not affected | Not affected |